I'm having very big trouble with viruses and spyware... I think they came from a website that popup'ed... well..
I have all kinds of different spyware-removers (ad-aware, xoftspy ect.) and AVG 7.0 antivirus (my norton is out of date)... Both find loads of crap, but they aren't able to remove the most of them! ARGH! And when I run full system scan with ad-aware, my laptop reboots... annoying! It seems that most og the viruses is in the C:\WINDOWS\isrvs\ folder, but I can't remove any of them.. I even used killbox.. Please help me!
HijackThis log goes here:
Logfile of HijackThis v1.99.1
Scan saved at 22:21:44, on 13-04-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Compaq\EAB\EabServr.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Tech\MagicBall\2.2\LWBWHEEL.exe
C:\Programmer\SlySoft\CloneCD\CloneCDTray.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Elgiganten\Application Data\oohw.exe
C:\WINDOWS\System32\r?gedit.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\Elgiganten\Skrivebord\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.tornbjerg-gym.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presar...=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.tornbjerg-gym.dk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = www.signon.stofanet.dk/proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.3 n-glx.s-redirect.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 newiframe.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 pizdato.biz
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 buldog-stats.com
O1 - Hosts: 127.0.0.3 www.buldog-stats.com
O1 - Hosts: 127.0.0.3 fregat.drocherway.com
O1 - Hosts: 127.0.0.3 slutmania.biz
O1 - Hosts: 127.0.0.3 www.slutmania.biz
O1 - Hosts: 127.0.0.3 toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.megapornix.com
O1 - Hosts: 127.0.0.3 megapornix.com
O1 - Hosts: 127.0.0.3 www.sp2[bleep]ed.biz
O1 - Hosts: 127.0.0.3 sp2[bleep]ed.biz
O1 - Hosts: 127.0.0.3 greg-tut.com
O1 - Hosts: 127.0.0.3 www.greg-tut.com
O1 - Hosts: 127.0.0.3 nylonsexy.com
O1 - Hosts: 127.0.0.3 www.nylonsexy.com
O1 - Hosts: 127.0.0.3 vparivalka.com
O1 - Hosts: 127.0.0.3 www.vparivalka.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {101C706E-B633-4136-8E50-BC682B5E6B2D} - C:\WINDOWS\System32\gbjkd.dll (file missing)
O2 - BHO: (no name) - {2E246FAE-8420-11D9-870D-000C2917DE7F} - (no file)
O2 - BHO: (no name) - {57A11CA8-8F46-9CBE-4B34-DC38703D91E7} - C:\WINDOWS\System32\qww.dll
O2 - BHO: (no name) - {81EA2309-A6D4-8A79-B539-EEE52EBD04F7} - C:\WINDOWS\System32\pdogporp.dll
O2 - BHO: (no name) - {A24B5051-6F33-41E3-6BD1-E019ACEB395C} - (no file)
O2 - BHO: (no name) - {B1C7137D-8B96-CE3A-9808-DAC81F8B29B1} - C:\WINDOWS\System32\pdogporp.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Programmer\ISTbar\istbarcm.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Tech\MagicBall\2.2\LWBWHEEL.exe
O4 - HKLM\..\Run: [delsaap] C:\WINDOWS\delsaap.exe
O4 - HKLM\..\Run: [delmsbb] C:\WINDOWS\delmsbb.exe
O4 - HKLM\..\Run: [Xjvdvkdd] C:\Program Files\Pwmjda\Guapir.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmer\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [Eif] C:\WINDOWS\Hfh.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Programmer\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Vpr] C:\WINDOWS\System32\Qup.exe
O4 - HKLM\..\Run: [Mnq] C:\WINDOWS\System32\Hoh.exe
O4 - HKLM\..\Run: [Htp] C:\WINDOWS\Def.exe
O4 - HKLM\..\Run: [Jfg] C:\WINDOWS\System32\Fpq.exe
O4 - HKLM\..\Run: [Adc] C:\WINDOWS\Cqh.exe
O4 - HKLM\..\Run: [Avi] C:\WINDOWS\Csf.exe
O4 - HKLM\..\Run: [Hnp] C:\WINDOWS\System32\Lqv.exe
O4 - HKLM\..\Run: [Sba] C:\WINDOWS\Cpl.exe
O4 - HKLM\..\Run: [Gld] C:\WINDOWS\Iqf.exe
O4 - HKLM\..\Run: [Dlf] C:\WINDOWS\System32\Pdg.exe
O4 - HKLM\..\Run: [Oaq] C:\WINDOWS\System32\Njo.exe
O4 - HKLM\..\Run: [Jut] C:\WINDOWS\Rud.exe
O4 - HKLM\..\Run: [Urb] C:\WINDOWS\Jar.exe
O4 - HKLM\..\Run: [Mrh] C:\WINDOWS\Bbr.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [Mvv] C:\WINDOWS\System32\Dca.exe
O4 - HKLM\..\Run: [Rhe] C:\WINDOWS\System32\Sbv.exe
O4 - HKLM\..\Run: [Tnu] C:\WINDOWS\Oal.exe
O4 - HKLM\..\Run: [Adk] C:\WINDOWS\System32\Lgm.exe
O4 - HKLM\..\Run: [Hqm] C:\WINDOWS\Qad.exe
O4 - HKLM\..\Run: [Poc] C:\WINDOWS\Hfq.exe
O4 - HKLM\..\Run: [Hbj] C:\WINDOWS\Olj.exe
O4 - HKLM\..\Run: [Cjq] C:\WINDOWS\Pah.exe
O4 - HKLM\..\Run: [Hkt] C:\WINDOWS\Nfb.exe
O4 - HKLM\..\Run: [Tde] C:\WINDOWS\Sjv.exe
O4 - HKLM\..\Run: [Ljf] C:\WINDOWS\System32\Brc.exe
O4 - HKLM\..\Run: [Bca] C:\WINDOWS\Chn.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Qnd] C:\WINDOWS\System32\Jdb.exe
O4 - HKLM\..\Run: [Iae] C:\WINDOWS\System32\Bol.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Esb] C:\WINDOWS\Ttv.exe
O4 - HKLM\..\Run: [Oio] C:\WINDOWS\System32\Fds.exe
O4 - HKLM\..\Run: [Kvq] C:\WINDOWS\System32\Nfp.exe
O4 - HKLM\..\Run: [Bpl] C:\WINDOWS\System32\Pkp.exe
O4 - HKLM\..\Run: [Anm] C:\WINDOWS\System32\Ilu.exe
O4 - HKLM\..\Run: [Gjn] C:\WINDOWS\System32\Tjq.exe
O4 - HKLM\..\Run: [Iru] C:\WINDOWS\System32\Hvj.exe
O4 - HKLM\..\Run: [Pdl] C:\WINDOWS\Avm.exe
O4 - HKLM\..\Run: [Tmk] C:\WINDOWS\Hif.exe
O4 - HKLM\..\Run: [Irp] C:\WINDOWS\System32\Lgg.exe
O4 - HKLM\..\Run: [Cou] C:\WINDOWS\System32\Chu.exe
O4 - HKLM\..\Run: [Hsr] C:\WINDOWS\System32\Cfi.exe
O4 - HKLM\..\Run: [San] C:\WINDOWS\System32\Ahc.exe
O4 - HKLM\..\Run: [Ipd] C:\WINDOWS\System32\Pbk.exe
O4 - HKLM\..\Run: [Nca] C:\WINDOWS\System32\Tjf.exe
O4 - HKLM\..\Run: [Thd] C:\WINDOWS\Hka.exe
O4 - HKLM\..\Run: [Mjk] C:\WINDOWS\Gir.exe
O4 - HKLM\..\Run: [Gek] C:\WINDOWS\Fam.exe
O4 - HKLM\..\Run: [Jtm] C:\WINDOWS\Ait.exe
O4 - HKLM\..\Run: [Dsp] C:\WINDOWS\System32\Ajj.exe
O4 - HKLM\..\Run: [Iir] C:\WINDOWS\Vhb.exe
O4 - HKLM\..\Run: [Nub] C:\WINDOWS\System32\Osl.exe
O4 - HKLM\..\Run: [Kdg] C:\WINDOWS\Mnu.exe
O4 - HKLM\..\Run: [Jrs] C:\WINDOWS\Ncb.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Ugb] C:\WINDOWS\Lkg.exe
O4 - HKLM\..\Run: [Tla] C:\WINDOWS\System32\Svp.exe
O4 - HKLM\..\Run: [Bpg] C:\WINDOWS\System32\Gjf.exe
O4 - HKLM\..\Run: [Kif] C:\WINDOWS\Fes.exe
O4 - HKLM\..\Run: [Tuf] C:\WINDOWS\Sch.exe
O4 - HKLM\..\Run: [Ohc] C:\WINDOWS\System32\Nrk.exe
O4 - HKLM\..\Run: [Lkd] C:\WINDOWS\System32\Bps.exe
O4 - HKLM\..\Run: [Tdt] C:\WINDOWS\System32\Okq.exe
O4 - HKLM\..\Run: [Epc] C:\WINDOWS\System32\Lro.exe
O4 - HKLM\..\Run: [Rvl] C:\WINDOWS\Hmi.exe
O4 - HKLM\..\Run: [Kjv] C:\WINDOWS\System32\Fro.exe
O4 - HKLM\..\Run: [Lsu] C:\WINDOWS\System32\Ccq.exe
O4 - HKLM\..\Run: [Rso] C:\WINDOWS\Qfi.exe
O4 - HKLM\..\Run: [Ktr] C:\WINDOWS\System32\Ugq.exe
O4 - HKLM\..\Run: [Pqn] C:\WINDOWS\System32\Phb.exe
O4 - HKLM\..\Run: [Gku] C:\WINDOWS\Aui.exe
O4 - HKLM\..\Run: [Trn] C:\WINDOWS\Vlu.exe
O4 - HKLM\..\Run: [Kua] C:\WINDOWS\Qhr.exe
O4 - HKLM\..\Run: [Pas] C:\WINDOWS\Fgn.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\ELGIGA~1\LOKALE~1\Temp\keep.exe
O4 - HKLM\..\Run: [Set] C:\WINDOWS\System32\Vga.exe
O4 - HKLM\..\Run: [Sav] C:\WINDOWS\Kkv.exe
O4 - HKLM\..\Run: [Uoa] C:\WINDOWS\Fbf.exe
O4 - HKLM\..\Run: [Smg] C:\WINDOWS\System32\Lhg.exe
O4 - HKLM\..\Run: [Lrl] C:\WINDOWS\Raj.exe
O4 - HKLM\..\Run: [Nsi] C:\WINDOWS\System32\Fqj.exe
O4 - HKLM\..\Run: [Eeq] C:\WINDOWS\Nfo.exe
O4 - HKLM\..\Run: [Qps] C:\WINDOWS\Gti.exe
O4 - HKLM\..\Run: [Prf] C:\WINDOWS\System32\Dvb.exe
O4 - HKLM\..\Run: [Rua] C:\WINDOWS\System32\Idu.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [Hip] C:\WINDOWS\Aqg.exe
O4 - HKLM\..\Run: [Rjo] C:\WINDOWS\System32\Avt.exe
O4 - HKLM\..\Run: [Kds] C:\WINDOWS\System32\Nts.exe
O4 - HKLM\..\Run: [Pae] C:\WINDOWS\Lnh.exe
O4 - HKLM\..\Run: [Hna] C:\WINDOWS\System32\Ukm.exe
O4 - HKLM\..\Run: [Uvg] C:\WINDOWS\System32\Bhh.exe
O4 - HKLM\..\Run: [Amt] C:\WINDOWS\System32\Sia.exe
O4 - HKLM\..\Run: [Afa] C:\WINDOWS\Out.exe
O4 - HKLM\..\Run: [Mnu] C:\WINDOWS\System32\Kks.exe
O4 - HKLM\..\Run: [Igk] C:\WINDOWS\Nuc.exe
O4 - HKLM\..\Run: [Mhn] C:\WINDOWS\System32\Hbo.exe
O4 - HKLM\..\Run: [Ggs] C:\WINDOWS\System32\Lmb.exe
O4 - HKLM\..\Run: [Hvs] C:\WINDOWS\Jjc.exe
O4 - HKLM\..\Run: [Elb] C:\WINDOWS\System32\Olg.exe
O4 - HKLM\..\Run: [Vdf] C:\WINDOWS\System32\Ere.exe
O4 - HKLM\..\Run: [Eqn] C:\WINDOWS\Htk.exe
O4 - HKLM\..\Run: [Lml] C:\WINDOWS\Ggc.exe
O4 - HKLM\..\Run: [Tdo] C:\WINDOWS\Lun.exe
O4 - HKLM\..\Run: [Lah] C:\WINDOWS\System32\Qna.exe
O4 - HKLM\..\Run: [Mhc] C:\WINDOWS\System32\Mkk.exe
O4 - HKLM\..\Run: [Cma] C:\WINDOWS\Qrk.exe
O4 - HKLM\..\Run: [Aic] C:\WINDOWS\System32\Thk.exe
O4 - HKLM\..\Run: [Fov] C:\WINDOWS\System32\Nkb.exe
O4 - HKLM\..\Run: [Sct] C:\WINDOWS\System32\Esb.exe
O4 - HKLM\..\Run: [Vei] C:\WINDOWS\System32\Blp.exe
O4 - HKLM\..\Run: [Goa] C:\WINDOWS\System32\Dng.exe
O4 - HKLM\..\Run: [Qlj] C:\WINDOWS\System32\Qkm.exe
O4 - HKLM\..\Run: [Kld] C:\WINDOWS\System32\Snc.exe
O4 - HKLM\..\Run: [Bea] C:\WINDOWS\System32\Sms.exe
O4 - HKLM\..\Run: [Rib] C:\WINDOWS\Mdu.exe
O4 - HKLM\..\Run: [Gau] C:\WINDOWS\Fts.exe
O4 - HKLM\..\Run: [Sjk] C:\WINDOWS\System32\Qeb.exe
O4 - HKLM\..\Run: [Stv] C:\WINDOWS\System32\Tac.exe
O4 - HKLM\..\Run: [Vuo] C:\WINDOWS\System32\Oak.exe
O4 - HKLM\..\Run: [Thi] C:\WINDOWS\System32\Lal.exe
O4 - HKLM\..\Run: [Udh] C:\WINDOWS\Dcg.exe
O4 - HKLM\..\Run: [Gaf] C:\WINDOWS\System32\Fbk.exe
O4 - HKLM\..\Run: [Ovo] C:\WINDOWS\System32\Hnk.exe
O4 - HKLM\..\Run: [Pjv] C:\WINDOWS\System32\Bdv.exe
O4 - HKLM\..\Run: [Idg] C:\WINDOWS\System32\Feh.exe
O4 - HKLM\..\Run: [Eku] C:\WINDOWS\Btu.exe
O4 - HKLM\..\Run: [Njj] C:\WINDOWS\System32\Vnk.exe
O4 - HKLM\..\Run: [Dni] C:\WINDOWS\Nlu.exe
O4 - HKLM\..\Run: [Kvj] C:\WINDOWS\System32\Hdi.exe
O4 - HKLM\..\Run: [Ctg] C:\WINDOWS\Cvm.exe
O4 - HKLM\..\Run: [Nph] C:\WINDOWS\System32\Keb.exe
O4 - HKLM\..\Run: [Ofi] C:\WINDOWS\System32\Oer.exe
O4 - HKLM\..\Run: [Dbe] C:\WINDOWS\Vhb.exe
O4 - HKLM\..\Run: [Smn] C:\WINDOWS\Evb.exe
O4 - HKLM\..\Run: [Lne] C:\WINDOWS\Tul.exe
O4 - HKLM\..\Run: [Vgg] C:\WINDOWS\System32\Gpk.exe
O4 - HKLM\..\Run: [Rnl] C:\WINDOWS\Her.exe
O4 - HKLM\..\Run: [Apr] C:\WINDOWS\System32\Knp.exe
O4 - HKLM\..\Run: [Ucc] C:\WINDOWS\System32\Tgb.exe
O4 - HKLM\..\Run: [Cub] C:\WINDOWS\System32\Gmv.exe
O4 - HKLM\..\Run: [Vlo] C:\WINDOWS\Kmg.exe
O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Programmer\XoftSpy\XoftSpy.exe" -b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [delmsbb] C:\WINDOWS\delmsbb.exe
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [Eif] C:\WINDOWS\Hfh.exe
O4 - HKCU\..\Run: [Vpr] C:\WINDOWS\System32\Qup.exe
O4 - HKCU\..\Run: [Mnq] C:\WINDOWS\System32\Hoh.exe
O4 - HKCU\..\Run: [Htp] C:\WINDOWS\Def.exe
O4 - HKCU\..\Run: [Jfg] C:\WINDOWS\System32\Fpq.exe
O4 - HKCU\..\Run: [Adc] C:\WINDOWS\Cqh.exe
O4 - HKCU\..\Run: [Avi] C:\WINDOWS\Csf.exe
O4 - HKCU\..\Run: [Hnp] C:\WINDOWS\System32\Lqv.exe
O4 - HKCU\..\Run: [Sba] C:\WINDOWS\Cpl.exe
O4 - HKCU\..\Run: [Gld] C:\WINDOWS\Iqf.exe
O4 - HKCU\..\Run: [Dlf] C:\WINDOWS\System32\Pdg.exe
O4 - HKCU\..\Run: [Oaq] C:\WINDOWS\System32\Njo.exe
O4 - HKCU\..\Run: [Jut] C:\WINDOWS\Rud.exe
O4 - HKCU\..\Run: [Urb] C:\WINDOWS\Jar.exe
O4 - HKCU\..\Run: [Mrh] C:\WINDOWS\Bbr.exe
O4 - HKCU\..\Run: [Mvv] C:\WINDOWS\System32\Dca.exe
O4 - HKCU\..\Run: [Rhe] C:\WINDOWS\System32\Sbv.exe
O4 - HKCU\..\Run: [Tnu] C:\WINDOWS\Oal.exe
O4 - HKCU\..\Run: [Adk] C:\WINDOWS\System32\Lgm.exe
O4 - HKCU\..\Run: [Hqm] C:\WINDOWS\Qad.exe
O4 - HKCU\..\Run: [Poc] C:\WINDOWS\Hfq.exe
O4 - HKCU\..\Run: [Hbj] C:\WINDOWS\Olj.exe
O4 - HKCU\..\Run: [Cjq] C:\WINDOWS\Pah.exe
O4 - HKCU\..\Run: [Hkt] C:\WINDOWS\Nfb.exe
O4 - HKCU\..\Run: [Tde] C:\WINDOWS\Sjv.exe
O4 - HKCU\..\Run: [Ljf] C:\WINDOWS\System32\Brc.exe
O4 - HKCU\..\Run: [Tssn] C:\Documents and Settings\Elgiganten\Application Data\oohw.exe
O4 - HKCU\..\Run: [Xmojdzji] C:\WINDOWS\System32\r?gedit.exe
O4 - HKCU\..\Run: [Bca] C:\WINDOWS\Chn.exe
O4 - HKCU\..\Run: [Qnd] C:\WINDOWS\System32\Jdb.exe
O4 - HKCU\..\Run: [Iae] C:\WINDOWS\System32\Bol.exe
O4 - HKCU\..\Run: [Esb] C:\WINDOWS\Ttv.exe
O4 - HKCU\..\Run: [Oio] C:\WINDOWS\System32\Fds.exe
O4 - HKCU\..\Run: [Kvq] C:\WINDOWS\System32\Nfp.exe
O4 - HKCU\..\Run: [Bpl] C:\WINDOWS\System32\Pkp.exe
O4 - HKCU\..\Run: [Anm] C:\WINDOWS\System32\Ilu.exe
O4 - HKCU\..\Run: [Gjn] C:\WINDOWS\System32\Tjq.exe
O4 - HKCU\..\Run: [Iru] C:\WINDOWS\System32\Hvj.exe
O4 - HKCU\..\Run: [Tmk] C:\WINDOWS\Hif.exe
O4 - HKCU\..\Run: [Irp] C:\WINDOWS\System32\Lgg.exe
O4 - HKCU\..\Run: [Cou] C:\WINDOWS\System32\Chu.exe
O4 - HKCU\..\Run: [Hsr] C:\WINDOWS\System32\Cfi.exe
O4 - HKCU\..\Run: [San] C:\WINDOWS\System32\Ahc.exe
O4 - HKCU\..\Run: [Ipd] C:\WINDOWS\System32\Pbk.exe
O4 - HKCU\..\Run: [Nca] C:\WINDOWS\System32\Tjf.exe
O4 - HKCU\..\Run: [Thd] C:\WINDOWS\Hka.exe
O4 - HKCU\..\Run: [Mjk] C:\WINDOWS\Gir.exe
O4 - HKCU\..\Run: [Gek] C:\WINDOWS\Fam.exe
O4 - HKCU\..\Run: [Nub] C:\WINDOWS\System32\Osl.exe
O4 - HKCU\..\Run: [Kdg] C:\WINDOWS\Mnu.exe
O4 - HKCU\..\Run: [Jrs] C:\WINDOWS\Ncb.exe
O4 - HKCU\..\Run: [Ugb] C:\WINDOWS\Lkg.exe
O4 - HKCU\..\Run: [Tla] C:\WINDOWS\System32\Svp.exe
O4 - HKCU\..\Run: [Bpg] C:\WINDOWS\System32\Gjf.exe
O4 - HKCU\..\Run: [Kif] C:\WINDOWS\Fes.exe
O4 - HKCU\..\Run: [Tuf] C:\WINDOWS\Sch.exe
O4 - HKCU\..\Run: [Ohc] C:\WINDOWS\System32\Nrk.exe
O4 - HKCU\..\Run: [Lkd] C:\WINDOWS\System32\Bps.exe
O4 - HKCU\..\Run: [Tdt] C:\WINDOWS\System32\Okq.exe
O4 - HKCU\..\Run: [Epc] C:\WINDOWS\System32\Lro.exe
O4 - HKCU\..\Run: [Rvl] C:\WINDOWS\Hmi.exe
O4 - HKCU\..\Run: [Kjv] C:\WINDOWS\System32\Fro.exe
O4 - HKCU\..\Run: [Rso] C:\WINDOWS\Qfi.exe
O4 - HKCU\..\Run: [Ktr] C:\WINDOWS\System32\Ugq.exe
O4 - HKCU\..\Run: [Pqn] C:\WINDOWS\System32\Phb.exe
O4 - HKCU\..\Run: [Gku] C:\WINDOWS\Aui.exe
O4 - HKCU\..\Run: [Trn] C:\WINDOWS\Vlu.exe
O4 - HKCU\..\Run: [Kua] C:\WINDOWS\Qhr.exe
O4 - HKCU\..\Run: [Pas] C:\WINDOWS\Fgn.exe
O4 - HKCU\..\Run: [Set] C:\WINDOWS\System32\Vga.exe
O4 - HKCU\..\Run: [Sav] C:\WINDOWS\Kkv.exe
O4 - HKCU\..\Run: [Uoa] C:\WINDOWS\Fbf.exe
O4 - HKCU\..\Run: [Smg] C:\WINDOWS\System32\Lhg.exe
O4 - HKCU\..\Run: [Lrl] C:\WINDOWS\Raj.exe
O4 - HKCU\..\Run: [Nsi] C:\WINDOWS\System32\Fqj.exe
O4 - HKCU\..\Run: [Eeq] C:\WINDOWS\Nfo.exe
O4 - HKCU\..\Run: [Qps] C:\WINDOWS\Gti.exe
O4 - HKCU\..\Run: [Prf] C:\WINDOWS\System32\Dvb.exe
O4 - HKCU\..\Run: [Rua] C:\WINDOWS\System32\Idu.exe
O4 - HKCU\..\Run: [Hip] C:\WINDOWS\Aqg.exe
O4 - HKCU\..\Run: [Rjo] C:\WINDOWS\System32\Avt.exe
O4 - HKCU\..\Run: [Kds] C:\WINDOWS\System32\Nts.exe
O4 - HKCU\..\Run: [Pae] C:\WINDOWS\Lnh.exe
O4 - HKCU\..\Run: [Hna] C:\WINDOWS\System32\Ukm.exe
O4 - HKCU\..\Run: [Uvg] C:\WINDOWS\System32\Bhh.exe
O4 - HKCU\..\Run: [Amt] C:\WINDOWS\System32\Sia.exe
O4 - HKCU\..\Run: [Afa] C:\WINDOWS\Out.exe
O4 - HKCU\..\Run: [Mnu] C:\WINDOWS\System32\Kks.exe
O4 - HKCU\..\Run: [Igk] C:\WINDOWS\Nuc.exe
O4 - HKCU\..\Run: [Mhn] C:\WINDOWS\System32\Hbo.exe
O4 - HKCU\..\Run: [Ggs] C:\WINDOWS\System32\Lmb.exe
O4 - HKCU\..\Run: [Hvs] C:\WINDOWS\Jjc.exe
O4 - HKCU\..\Run: [Elb] C:\WINDOWS\System32\Olg.exe
O4 - HKCU\..\Run: [Vdf] C:\WINDOWS\System32\Ere.exe
O4 - HKCU\..\Run: [Eqn] C:\WINDOWS\Htk.exe
O4 - HKCU\..\Run: [Lml] C:\WINDOWS\Ggc.exe
O4 - HKCU\..\Run: [Tdo] C:\WINDOWS\Lun.exe
O4 - HKCU\..\Run: [Lah] C:\WINDOWS\System32\Qna.exe
O4 - HKCU\..\Run: [Mhc] C:\WINDOWS\System32\Mkk.exe
O4 - HKCU\..\Run: [Cma] C:\WINDOWS\Qrk.exe
O4 - HKCU\..\Run: [Aic] C:\WINDOWS\System32\Thk.exe
O4 - HKCU\..\Run: [Fov] C:\WINDOWS\System32\Nkb.exe
O4 - HKCU\..\Run: [Sct] C:\WINDOWS\System32\Esb.exe
O4 - HKCU\..\Run: [Vei] C:\WINDOWS\System32\Blp.exe
O4 - HKCU\..\Run: [Goa] C:\WINDOWS\System32\Dng.exe
O4 - HKCU\..\Run: [Qlj] C:\WINDOWS\System32\Qkm.exe
O4 - HKCU\..\Run: [Kld] C:\WINDOWS\System32\Snc.exe
O4 - HKCU\..\Run: [Bea] C:\WINDOWS\System32\Sms.exe
O4 - HKCU\..\Run: [Rib] C:\WINDOWS\Mdu.exe
O4 - HKCU\..\Run: [Gau] C:\WINDOWS\Fts.exe
O4 - HKCU\..\Run: [Sjk] C:\WINDOWS\System32\Qeb.exe
O4 - HKCU\..\Run: [Stv] C:\WINDOWS\System32\Tac.exe
O4 - HKCU\..\Run: [Vuo] C:\WINDOWS\System32\Oak.exe
O4 - HKCU\..\Run: [Thi] C:\WINDOWS\System32\Lal.exe
O4 - HKCU\..\Run: [Udh] C:\WINDOWS\Dcg.exe
O4 - HKCU\..\Run: [Gaf] C:\WINDOWS\System32\Fbk.exe
O4 - HKCU\..\Run: [Ovo] C:\WINDOWS\System32\Hnk.exe
O4 - HKCU\..\Run: [Pjv] C:\WINDOWS\System32\Bdv.exe
O4 - HKCU\..\Run: [Idg] C:\WINDOWS\System32\Feh.exe
O4 - HKCU\..\Run: [Eku] C:\WINDOWS\Btu.exe
O4 - HKCU\..\Run: [Njj] C:\WINDOWS\System32\Vnk.exe
O4 - HKCU\..\Run: [Dni] C:\WINDOWS\Nlu.exe
O4 - HKCU\..\Run: [Kvj] C:\WINDOWS\System32\Hdi.exe
O4 - HKCU\..\Run: [Ctg] C:\WINDOWS\Cvm.exe
O4 - HKCU\..\Run: [Nph] C:\WINDOWS\System32\Keb.exe
O4 - HKCU\..\Run: [Ofi] C:\WINDOWS\System32\Oer.exe
O4 - HKCU\..\Run: [Dbe] C:\WINDOWS\Vhb.exe
O4 - HKCU\..\Run: [Smn] C:\WINDOWS\Evb.exe
O4 - HKCU\..\Run: [Lne] C:\WINDOWS\Tul.exe
O4 - HKCU\..\Run: [Vgg] C:\WINDOWS\System32\Gpk.exe
O4 - HKCU\..\Run: [Rnl] C:\WINDOWS\Her.exe
O4 - HKCU\..\Run: [Apr] C:\WINDOWS\System32\Knp.exe
O4 - HKCU\..\Run: [Ucc] C:\WINDOWS\System32\Tgb.exe
O4 - HKCU\..\Run: [Cub] C:\WINDOWS\System32\Gmv.exe
O4 - HKCU\..\Run: [Vlo] C:\WINDOWS\Kmg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {01C6176D-BFBC-45B8-A06E-2A554E06FA86} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {01C6176D-BFBC-45B8-A06E-2A554E06FA86} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {18E42155-0793-4446-8700-E6D28A35A048} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {18E42155-0793-4446-8700-E6D28A35A048} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {342E7606-33B3-4A8C-98B1-039AC221F5E9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {342E7606-33B3-4A8C-98B1-039AC221F5E9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {35CC58EB-DDAA-49D7-861E-88BBD7055FD0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {35CC58EB-DDAA-49D7-861E-88BBD7055FD0} - (no file) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Programmer\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {BBDDDC57-692F-4F9D-B7C0-6602C5962591} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BBDDDC57-692F-4F9D-B7C0-6602C5962591} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F000FC6F-9E0A-473B-975F-82288DA449B6} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F000FC6F-9E0A-473B-975F-82288DA449B6} - (no file) (HKCU)
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c283.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.dans...vex/DB/Menu.cab
O16 - DPF: {5CE8C9BE-B561-4311-8C03-D6F6C1CAF7E1} (CSND_AX.ctlCSND_AX) - http://h71025.www7.h...ect/CSND_AX.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.axis.com/...sCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.dans...B/e-Safekey.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq....co/SysQuery.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.dans...anskeSikker.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
thanks.
Edited by yuran, 13 April 2005 - 02:33 PM.